The real problem is actually, not an architectural one.

Security standards dictate that no device, no matter what its function, span
2 networks of differing security domains.  This is an attempt to see if
there was a way we could safely work around this.

The hosts on the network segment to be scanned are not considered hostile,
but since they are in a lower security domain, we need to technically
consider them hostile, to consider them as if they had been compromised.

Other than ipchains\iptables firewalling, any other suggestions?

-----Original Message-----
From: Rob Nelson [mailto:[EMAIL PROTECTED]]
Sent: Thursday, January 24, 2002 9:53 AM
To: Perciaccante, Robert
Subject: RE: Nessus on "blind" interface


>The overall concept is this.  Eth1 is used to collect results, change
>.nessusrc files, etc.  Eth0 is on a DMZ, and if bound to an IP address, is
>vulnerable to attack from anyone on this segment.
>
>If Nessus was able to send packets out with spoofed IP/MAC addresses, and
>then sniff the results off the wire, it could perform the necessary scans,
>but not itself be vulnerable to attack on that segment.

If you're worried about a host you're scanning attacking you, then even with

IP/MAC spoofing, you'd still be vulnerable because they'd have to have some 
way to respond to your probes. The best you could do is possibly run each
test 
after changing to a random unused IP address on the segment - run one test 
from 10.0.0.14, the next from 10.0.0.241, etc. But that's pretty complex for

what you *should* do - ifup eth0, nessus probe the target, ifdown eth0.
You're 
not going to become invulnerable from attack when you're scanning no matter 
what, you just mitigate who you're vulnerable to.

The only other thing I can think of is to use something like ipchains or 
ipfilter to block all traffic except from the IP you're scanning...which 
requires re-applying rulesets between each host you scan. Pretty tedious.

Rob Nelson
[EMAIL PROTECTED]

Reply via email to